Uganda and Zimbabwe’s Fourth-Cycle UPRs Must Turn Digital Progress into Stronger Rights Protections 

By Patricia Ainembabazi |

As Uganda and Zimbabwe prepare for their fourth-cycle Universal Periodic Reviews (UPRs) at the United Nations Human Rights Council, stakeholder submissions by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) and partners on the two countries reveal a common challenge: digital infrastructure and legislation are advancing, but the protection of human rights online is not keeping pace.

Both countries have made notable progress since their previous UPR reviews in January 2022, including advances in digital infrastructure, regulatory frameworks, and access to digital services. Uganda has expanded its communications infrastructure and digital public services, strengthened aspects of data protection enforcement, and registered important court decisions annulling provisions of the Computer Misuse (Amendment) Act, 2022, and criminal defamation offences.

Zimbabwe has expanded internet and broadband subscriptions, licensed satellite internet services, adopted regulations to support the Freedom of Information Act, 2020, and introduced a data protection framework through the Cyber and Data Protection Act, 2021.

However, these developments have not consistently translated into safe, affordable, and rights-respecting participation online. For instance, freedom of expression remains under pressure in both countries. Journalists, activists, opposition actors, artists, comedians, human rights defenders, and social media users continue to face arrest, prosecution, intimidation, and harassment over their expression.

While Uganda’s court decisions have provided important protections, broadly framed communication offences and online media licensing requirements continue to create uncertainty and encourage self-censorship. In Zimbabwe, offences relating to false information, cyberbullying, incitement, insulting the President, sovereignty, and national interest threaten journalism, political debate, satire, whistleblowing, and human rights advocacy.

The joint submission on Uganda by CIPESA, the Association for Progressive Communications (APC), and Women of Uganda Network (UWOGNET) underlines the growing relationship between internet access and democratic participation. A similar dynamic is seen in the joint submission on Zimbabwe by Zimbabwe Lawyers for Human Rights (ZLHR), the University of Birmingham, Pan African Lawyers Union (PALU), the Digital Rights Alliance Africa (DRAA), and CIPESA.

During Uganda’s January 2026 general elections, the government imposed an internet shutdown lasting almost five days, disrupting communication, access to information, economic activity, digital financial services, and participation in public affairs. It marked the third consecutive election cycle in which the country disrupted digital communications, following similar measures in 2016 and 2021.

Zimbabwe experienced network degradation during its 2023 elections. Although internet connectivity has expanded in both countries, these network disruptions demonstrate the need for safeguards against shutdowns, throttling, and other forms of communication interference during elections and periods of political contestation.

Affordability and inequality also remain obstacles in both countries. While Uganda recorded 47.1 million active mobile subscriptions and 18.5 million active internet subscriptions by December 2025, taxes on data, airtime, devices, and digital services continue to make connectivity unaffordable to a large number of Ugandans.

In Zimbabwe, high data and device costs, unreliable electricity, rural infrastructure gaps, limited digital literacy, and inaccessible services prevent many people from fully participating online. Across both countries, women, rural communities, students, older persons, low-income households, and persons with disabilities face disproportionate barriers to affording and using digital technologies.

Privacy and surveillance are equally pressing challenges. Uganda’s expanding use of biometric identification, iris scans, closed-circuit television systems, digital number plates, and electoral technologies requires stronger safeguards, transparency, and independent oversight. Proposed social media monitoring tools raise additional concerns regarding privacy, freedom of expression, and accountability. The Personal Data Protection Office also needs adequate institutional capacity to effectively enforce the law.

In Zimbabwe, the designation of the Postal and Telecommunications Regulatory Authority of Zimbabwe as the Data Protection Authority raises concerns about institutional independence. Broad national security exemptions and limited judicial oversight of surveillance powers also expose individuals to possible violations of privacy.

Another shared concern is technology-facilitated gender-based violence. Women journalists, politicians, activists, and human rights defenders face cyberstalking, doxing, impersonation, sexualised disinformation, threats, coordinated harassment, and the non-consensual sharing of intimate images. Artificial intelligence is increasing these risks by enabling sexual deepfakes and other manipulated content intended to discredit women and exclude them from public life.

The fourth-cycle reviews should result in clear and measurable commitments. Accordingly, Uganda and Zimbabwe should:

  1. Reform restrictive expression laws and repeal vague offences used against legitimate journalism, criticism, satire, and political participation.
  2. Prohibit internet shutdowns, throttling, and arbitrary platform blocking, particularly during elections, protests, and other periods of heightened public interest.
  3. Promote affordable and inclusive connectivity by reducing service costs, expanding rural infrastructure, improving accessibility, and supporting community-centred connectivity models.
  4. Strengthen access to information through proactive disclosure, accessible request procedures, and effective implementation of existing laws.
  5. Guarantee independent data protection and surveillance oversight, including judicial authorisation, transparency reporting, and remedies for unlawful surveillance or misuse of personal data.
  6. Adopt survivor-centered responses to technology-facilitated gender-based violence, supported by accessible reporting systems, legal assistance, and stronger platform accountability.

The UPR provides both governments with an opportunity to show that digital transformation and human rights protection are mutually reinforcing. Progress must be measured not only through infrastructure, subscription numbers, and legislation, but by whether people can communicate, organise, access information, and participate online freely, safely, and without discrimination.

For the full reports as submitted, click here for Uganda and here for Zimbabwe.

Rethinking Africa’s Approach to the Politics of AI Governance and Regulation

By Paul Kimumwe |

The past few years have witnessed a growing urgency for frameworks that regulate and harness the development and implementation of new and emerging technologies, especially Generative Artificial Intelligence (Gen AI).

At the international and regional level, the United Nations (UN) and the African Union (AU) have established norms through resolutions, strategies and guidelines to affirm the relationship between technology and human rights, and provide benchmarks for Member States developing rights-respecting AI governance and regulatory frameworks.

In March 2024, the UN adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that also benefit sustainable development. The resolution also calls upon Member States and other stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”

The 2024 resolution reaffirmed that “the same rights that people have offline must also be protected online, including throughout the life cycle of artificial intelligence systems.” It called upon member states to ensure that national AI governance and regulatory frameworks “promote safe, secure and trustworthy artificial intelligence systems” that are inclusive and benefit everyone in an equal manner.

In August 2025, the UN adopted resolution 79/325, establishing the Independent International Scientific Panel on AI and Global Dialogue on AI Governance. It aims to provide a platform to discuss international cooperation, share best practices and lessons learned, and to facilitate open, transparent and inclusive discussions on AI governance. However, a year earlier, in July 2024, the AU adopted the Continental AI Strategy, which emphasises the development of robust governance regimes for AI founded on ethical principles, democratic values, human rights, and the rule of law, in line with the AU  Agenda 2063.

Both the UN resolutions on AI and the AU continental strategy came on the backdrop of other AI-related policy guidelines such as Center for AI and Digital Policy’s 2018 Universal Guidelines for AI, the Organization for Economic Cooperation and Development (OECD) 2019 AI Principles / G20 AI Guidelines, the United Nations Education Scientific and Cultural Organization (UNESCO’s) 2021 Recommendation on the Ethics of AI, and the European Union Commission’s (EUC) 2024 European Union AI Act.

Many African countries have been actively developing AI-related laws, policies, and strategies. Rwanda was the first to adopt a national AI policy in 2019, followed by Ghana’s National Artificial Intelligence Strategy in October 2022, Egypt’s National Artificial Intelligence Strategy in January 2025, and Kenya’s own strategy in May 2025. Benin, Côte d’Ivoire, Ethiopia, Mauritius, Nigeria, Tunisia, Zambia, and Zimbabwe are among others that have developed AI policies or strategies. Others, such as Burkina Faso, Guinea, Lesotho, Mali, Namibia, and Uganda, are still at different stages in developing their AI policies or strategies.

A case of history repeating itself?

While all these have been welcome developments in the governance and regulation of AI, studies show that the adoption of international and regional human rights instruments and national laws, policies and strategies is often just the first step in a long process. If not well managed, it often results in provisions that are, although of a progressive nature, are hard to implement and fail to address local needs and realities.

This is because the process of drafting these laws and strategies in many developing contexts is often devoid of meaningful multistakeholder consultations and engagement. Moreover, there has also been a tendency to adopt and replicate models from the global North, whose texts, while progressive, have faced strong resistance from Member States as they sometimes do not align with local contexts and cultural norms.

For example, many African countries, including Algeria, Ethiopia, Cameroon, Kenya, Mauritius, Namibia, Rwanda, South Africa, and Uganda, expressed strong reservations about certain provisions contained in the Protocol to the African Charter on Human and People’s Rights on the Rights of Women in Africa (Maputo Protocol).

Additionally, most of these models are state-centric and grounded in frameworks that create a distinct binary between duty-bearers and rights-holders, but do not articulate how and what each party needs to do to ensure meaningful implementation of the initiatives.

While the state-centric and rights-based approaches may seem attractive, in practice, their relevance in advancing digital rights is often undermined, especially when the prescribed provisions and action points do not align with the country’s current social, economic and political realities. Indeed, cases abound in which initial promises have fizzled over time due to the political leadership’s inaction (and sometimes unwillingness) to fully adopt and implement the resolutions or strategies.

For example, it took almost nine years for the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) to enter into force on June 8, 2023, after its adoption in 2014. Indeed, more countries (40) have enacted data protection laws as compared to those that have ratified (16), highlighting a disconnect between national legal reforms and their commitment to continental frameworks. Similarly, the AU Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa, adopted on January 30, 2018, took six years to enter into force, after the 15th ratification was achieved.

More critically, however, the lack of political will often reflect in the absence of clearly defined funding mechanisms for the implementation of these policies and strategies. As a result, even well-designed and progressive frameworks face implementation challenges due to structural flaws and insufficient funding.

For example, while Africa has scored highly in enacting Data Protection laws, which have become central to ongoing AI governance frameworks, one issue affecting their effective implementation is the lack of clear funding mechanisms for the regulatory bodies responsible for oversight and implementation. Other challenges include weak governance structures that deny these oversight bodies financial, decisional and operational independence and place them under the supervision of political appointees rather than parliament.

Designing for Failure?

Apart from Kenya, most African countries that have developed or are in the process of developing an AI strategy or policy do not provide for budgetary allocations or estimates for the implementation of their AI strategies, laws or policies. Countries such as Rwanda provide for a project-level funding framework, while others, such as Egypt and Mauritius, rely on programmatic budgets to fund the implementation of their strategies.

Even then, while implementation of Kenya’s National Artificial Intelligence Strategy (2025–2030) was costed at KSh 152 billion over a period of five years, a review of Kenya’s 2026/27 national budget shows no dedicated funding allocation for the strategy. Instead, the Sh8.6 billion allocated to the ICT sector mainly targets the expansion of broadband access, the strengthening of digital skills, and the digitisation of government services.

Additionally, in countries such as Ethiopia and Rwanda, while the policies provide for the establishment of an implementation body, several functions have been split across different ministries, departments and agencies (MDAs), which, in practice, would pose a significant challenge to meaningful execution.

For example, Rwanda’s AI policy mandates the Responsible AI office under the Ministry of ICT and Innovation to be responsible for effective tech implementation. It also positions the Rwanda Utilities Regulatory Authority (RURA) as the technical regulator responsible for developing ethical AI guidelines and principles, and the National Cyber Security Authority (NCSA) to oversee data protection compliance relevant to AI systems.

In Ethiopia, the policy designates the Ethiopian Artificial Intelligence Institute (EAII) as the national coordinating body responsible for implementation, standards development, and capacity building, and the Ministry of Innovation and Technology is responsible for providing policy oversight. Other sectoral agencies, such as the Ethiopian Communications Authority (ECA), the Ministry of Health, and the National Bank, have mandates over telecommunications and data matters, health-sector-related AI, and financial AI, respectively.

While a multisectoral approach to policy and strategic implementation can improve cohesiveness and legitimacy, the approach is prone to risks such as divergent priorities, internal conflicts, power struggles, and regulatory fragmentation, which are likely to affect how the policies and strategies are executed.

Implications for the Future of AI Governance and Regulation

In many African countries, the development of AI governance and regulatory structures is still in its infancy and presents a unique opportunity for Africans to shape their own destiny on how AI should be developed and deployed in ways that respond to and respect local needs and contexts.

Enactment of AI-specific Laws

In many countries, governments are relying on existing laws, such as data protection, communications, and cyber-related legislation, alongside the AI policies and strategies being developed. Given the evolving nature of AI, countries need to work towards enacting AI-specific laws that clearly define and contextualise AI.

Empowering the Oversight Bodies

As currently structured, many of the existing and proposed oversight bodies are either not yet operational or lack a clear mandate and sufficient resources for effective oversight. Additionally, many of them are situated within fragmented regulatory environments with overlapping responsibilities, which results in uncoordinated implementation. It is important, therefore, that the mandate of the oversight bodies and resources are clearly defined and guaranteed to ensure independence and eliminate the possibility of political interference.

Meaningful Stakeholder Participation

Having empowered stakeholders who are meaningfully engaged and participate in the development processes for policies, laws and strategies is critical to ensuring that the resulting instruments address real needs, are people-centred and implementable, and have government buy-in, as reflected in the government’s funded priorities.

Adopting a Human Rights-Centred Approach

A 2025 study by CIPESA shows that in many countries, the adoption of a human rights-centred approach to AI governance remains aspirational due to gaps in implementation, technical capacity, and stakeholder engagement in policy development and implementation. It is important, therefore, that current efforts prioritise safeguarding fundamental human rights and freedoms, enhancing human capabilities over replacement, and ensuring meaningful human control, transparency, fairness, and inclusivity in AI systems.

Shaping the Agenda for the Forum on Internet Freedom in Africa 2026 (FIFAfrica26): Thank You for Your Proposals

FIFAfrica26 |

The organisers of the upcoming Forum on Internet Freedom in Africa 2026 (FIFAfrica26) extend sincere appreciation to everyone who submitted a session proposal or travel support application in response to the recent Call.

We received over 450 submissions, reflecting a rich diversity of interests spanning the current digital rights landscape in Africa and their intersections with global dynamics. The submissions collectively reflected the pressing issues shaping digital rights, online freedoms, and internet governance across the continent while also highlighting the vibrant community working to advance internet freedom in Africa.

Successful Applicants

Successful applicants have been notified directly. We are excited to confirm that their sessions and contributions will form the core of the Forum’s agenda. We look forward to working closely with them to shape the programme and to bringing their insightful proposals to life during the Forum.

For Those Not Selected

If you have not received a success notification, please know that this does not reflect a lack of value in your submission. The volume of high-quality proposals far exceeded the available session slots, and difficult decisions had to be made. We remain grateful for your engagement and encourage you to stay connected with the Forum as there will be future opportunities to contribute.

Next Steps in the Process

  • The FIFAfrica26 agenda will be shared publicly in the coming weeks.
  • All applicants will continue to receive Forum updates and are warmly invited to attend as participants online or in person.
  • Registration to attend the Forum remains open: secure your seat here.

Plan Your Travel to Mauritius

The Forum will be hosted at the InterContinental Resort, Fort Coastal Road, MU, Balaclava 21306, Mauritius. All participants, those receiving travel support from CIPESA and other partners as well as independent participants, should refer to the FIFAfrica26 travel note and plan accordingly.

Thank you once again for your time, expertise, and commitment to building a free, open, and inclusive internet in Africa. We look forward to engaging with you online or in person at FIFAfrica26.

Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa

By CIPESA Writer |

Digital platforms have become central to how millions of Africans access news, organise politically, run businesses, and participate in public life. Yet the companies that operate these platforms make far-reaching decisions about what people see online, whose voices are amplified, and how public debate unfolds, often with limited accountability to the communities they affect.

As platforms increasingly rely on artificial intelligence and automated systems to recommend, rank, and moderate content, questions about transparency, oversight, and responsibility have become more urgent.

Governments across Africa are beginning to answer the question of who governs the platforms in different ways. CIPESA’s latest policy brief, Platform Governance in Africa: Emerging Models and Policy Priorities, examines how Nigeria, South Africa, and Uganda have confronted platform power, what their experiences reveal about the limits of national regulation, and why regional cooperation is becoming increasingly important.

Three Countries, Three Approaches

Nigeria has shown that African regulators can build credible cases and prevail in court. Following a joint investigation by the Federal Competition and Consumer Protection Commission and the Nigeria Data Protection Commission, Meta was found to have appropriated Nigerian users’ data without consent, abused its dominant market position, and treated Nigerian consumers less favourably than users elsewhere. In July 2024, regulators imposed a USD 220 million fine, which was later upheld on appeal.

Yet the case also illustrates the limits of enforcement. When the payment deadline expired in June 2025, neither Meta nor the regulator had publicly confirmed whether the fine had been paid. Nigeria demonstrated that regulators can win legal battles. Whether those victories translate into lasting changes in platform behaviour remains an open question.

South Africa has taken a different approach. Rather than relying primarily on financial penalties, the Competition Commission’s Media and Digital Platforms Market Inquiry sought to address how dominant platforms affect the sustainability of local journalism. The inquiry secured binding commitments from Google, Meta, TikTok, and Microsoft, including a ZAR 688 million (USD 41.6 million) media support package from Google. It represents one of Africa’s most ambitious efforts to address platform power through competition oversight, although its long-term impact will depend on sustained political commitment and regulatory capacity.

Uganda’s experience offers a different lesson. A government-ordered restriction on Facebook, imposed in January 2021 after Meta removed accounts linked to government-affiliated influence operations, has now lasted more than five years. The costs have largely been borne by Ugandan users and businesses, highlighting the wider social and economic consequences of unresolved disputes between governments and global platforms.

The Limits of Acting Alone

These cases highlight a central challenge of platform governance in Africa: legal authority does not always translate into practical leverage over global technology companies. Also, it is apparent that market size matters. Nigeria and South Africa, as two of Africa’s largest digital markets, secured stronger responses from platforms than Uganda did. Most African economies are considerably smaller than Meta’s annual profits, limiting the pressure individual governments can exert on multinational companies.

This reality is driving growing interest in regional approaches. The ongoing investigation by the Common Market for Eastern and Southern Africa (COMESA) Competition Commission into Meta’s practices across 21 member states reflects a shift towards collective oversight of platform power. By acting together, governments have greater potential to address competition, data governance, and digital market concerns than they do individually.

Why Platform Governance Matters

Platform governance is often discussed in terms of regulation and competition, yet users ultimately experience its consequences. During the conflict in Ethiopia’s Tigray region, platforms struggled to moderate harmful content in Tigrinya and Amharic. In one widely documented case, Facebook posts targeting university professor Meareg Amare remained online for days after being reported and were removed only after he had been killed.

Across Africa, women journalists, politicians, and activists continue to face technology-facilitated gender-based violence that platform governance systems have struggled to address effectively. These failures can discourage participation in public life and narrow the diversity of voices represented online.

Meanwhile, coordinated disinformation campaigns continue to spread faster than moderation and fact-checking systems can respond. A 2025 analysis in Kenya documented a coordinated campaign that generated more than 150,000 views in less than two weeks, illustrating how quickly harmful narratives can circulate before effective interventions are possible.

What Needs to Change

The policy brief argues that platform governance in Africa must extend beyond content moderation to broader questions of accountability, competition, data governance, and algorithmic transparency. Addressing these challenges will require governments to pursue rights-respecting regulation, regulators to strengthen oversight of platform systems, regional bodies to deepen cooperation, and platforms to provide greater transparency about how automated systems shape online experiences.

Platform governance in Africa is no longer only about removing harmful content. It is about who controls the infrastructure of public communication, on what terms, and with what accountability to the people who depend on it.

The experiences of Nigeria, South Africa, and Uganda show that African governments are increasingly willing to confront platform power. They also demonstrate that no African country can do so effectively in isolation. Building a more accountable digital future will require stronger institutions, deeper regional cooperation, and platforms that are genuinely responsive to the societies they serve.

To explore the evidence, country case studies, and policy recommendations in greater detail, read CIPESA’s full policy brief, Platform Governance in Africa: Emerging Models and Policy Priorities.

Cybercrime Laws, “False News” Offences, and Online Expression in Africa

By CIPESA Writer |

As African societies become increasingly digital, governments are grappling with the balance between the protection of citizens from online harms while preserving the fundamental freedoms of free expression, access to information and freedom to participate in governance.   

The legal tools adopted to address these challenges are raising an equally pressing concern. Cybercrime and so-called “false news” laws are increasingly extending beyond their stated purpose of combating digital harm and are instead being used to regulate political speech, suppress dissent, and narrow civic space.

This emerging tension sits at the heart of CIPESA’s latest policy brief, Cybercrime Laws, “False News” Offences, and Online Expression in Africa. Drawing on legislative developments, court decisions, and recent cases from select countries, the brief examines how cybercrime legislation has evolved into one of the defining governance issues of Africa’s digital era.

Many countries have introduced offences such as “false information”, “offensive communication”, “malicious communication”, and “harmful content”. While these provisions are often justified as necessary responses to online abuse, they frequently suffer from vague drafting and broad enforcement powers. This creates uncertainty about what constitutes unlawful speech and allows authorities considerable discretion in deciding who should face criminal investigation or prosecution.

In several African countries, journalists, activists, bloggers, opposition politicians, and ordinary citizens have been arrested or prosecuted for online expression that would ordinarily fall within the boundaries of legitimate public debate. At the same time, restrictions on online speech increasingly operate alongside expanding surveillance powers, internet shutdowns, and growing state control over digital communications, reinforcing broader patterns of digital authoritarianism.

Importantly, however, this is not simply a story of shrinking freedoms. Encouraging developments in several jurisdictions demonstrate that alternative approaches are both possible and necessary. Recent constitutional decisions in Uganda and Kenya have reaffirmed that restrictions on freedom of expression must be clearly defined, proportionate, and consistent with constitutional protections. Similarly, in Nigeria legislative reforms illustrate how sustained engagement by civil society can improve legal frameworks, even if implementation challenges persist.

These developments highlight an important policy lesson as to how regulation can effectively address genuine digital harms without criminalising legitimate expression or weakening democratic accountability.

This policy brief explores these issues in greater depth, examining the emerging patterns across Africa, the evolving role of national and regional courts, and the reforms needed to ensure that cybercrime regulation strengthens both digital security and democratic governance. It concludes that the future of digital freedom in Africa will depend on how governments, courts, regional institutions, and technology companies navigate this balance.

The brief sets out concrete recommendations for four groups of actors. Governments should repeal or amend vague offences, including those relating to false information, offensive communication, and similarly broad categories, that have been used to criminalise legitimate online expression. They should prioritise civil remedies over criminal sanctions in defamation and reputation-related disputes, refrain from imposing internet shutdowns, and ensure that any restrictions on freedom of expression comply with international human rights standards.

Legislators and regulators should ensure that cybercrime and digital governance laws comply with the principles of legality, necessity, and proportionality. They should also require human rights impact assessments before introducing new cybercrime or disinformation laws and establish meaningful public participation throughout the law-making processes. Laws developed without meaningful public scrutiny and civil society engagement are more likely to undermine rights than protect them.

Regional institutions should strengthen the monitoring and implementation of regional human rights commitments and promote common standards on digital rights and accountable digital governance to guide national legal reforms across the continent.

Finally, technology platforms should invest in African language content moderation and local contextual expertise, improve transparency around content moderation decisions and algorithmic decision making, and strengthen grievance and appeals mechanisms for users in African countries, where existing processes often remain inaccessible or ineffective.

Please read the full Policy Brief here.